Description |
This article describes an issue with RADIUS Accounting when using IKEv2 with a remote RADIUS User. When using IKEv2 with RADIUS authentication, RADIUS Accounting packets can be seen on the RADIUS Server for users on the RADIUS Server, however, when a 'Remote RADIUS User' config is used (in order to use FortiToken), there are no RADIUS Accounting packets. |
Scope | FortiOS. |
Solution |
FortiGate configuration.
RADIUS configuration:
Remote RADIUS User:
RADIUS User.
Group for testing with RADIUS User:
A capture on both scenarios shows that RADIUS Accounting packets are not being sent for the case when a Remote RADIUS user is being used.
RADIUS User: normal.user.
Remote RADIUS User: tobias.ahlfors.
Note: This is currently under investigation, and there is no fix available yet. This only affects IKEv2 with Remote RADIUS User, on IKEv1, there is no issue, so a possible workaround is to use IKEv1 if FortiToken is mandatory.
Related article: Technical Tip: Configure Fortinet Single Sign On (FSSO) for Dialup IPsec VPN users via Radius-Accoun... |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.